| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| agentguard-v1.1.1.cdx.json | 2026-09-24 | 18.5 kB | |
| agentguard-v1.1.1.spdx.json | 2026-09-24 | 28.4 kB | |
| AgentGuard v1.1.1 source code.tar.gz | 2026-09-24 | 1.2 MB | |
| AgentGuard v1.1.1 source code.zip | 2026-09-24 | 1.4 MB | |
| README.md | 2026-09-24 | 6.0 kB | |
| Totals: 5 Items | 2.7 MB | 0 | |
AgentGuard 1.1.1 — Release Notes
Released: 2026-09-23
Headline: A patch release that corrects what the docs got wrong about names, addresses and examples, and closes one proxy bind check. The TypeScript SDK is on npm for the first time, as @lictorate/agentguard.
If you sent a security, conduct or support report to
cauaferraz@gmail.com, it was never received. That address doesn't exist; earlier docs misspelled it. Please resend to cauaferrazp@gmail.com.
Why this release exists
An audit checked every install command, contact address, example config and documented behaviour against what actually exists. Most of what it found was in the docs, and some of it pointed users at things that aren't ours or don't exist:
- The TypeScript install command named someone else's package. The docs said
npm install @agentguard/sdk. That npm package belongs to an unrelated project; the AgentGuard SDK had never been published to npm. - The security contact address didn't exist, so vulnerability reports sent to it went nowhere.
- Three release notes said to
docker pullan image that was never published. - The example MCP configs launched a fetch server that has never existed on npm, and the default policy denied every call to the fetch and GitHub examples even after approval.
- One code bug:
agentguard-llm-proxy --listen :PORTstarted on every network interface with no inbound auth.
What changed
LLM API Proxy: --listen :PORT needs --proxy-api-key
A listen address with no host binds every interface, but the proxy treated it as loopback and skipped its rule that non-loopback binds require --proxy-api-key. It now refuses to start (exit status 2) and suggests 127.0.0.1:PORT. If you ran the proxy this way on a reachable host, anyone who could reach the port could send requests through it to your configured provider, each one policy-checked and audited under the proxy's AgentGuard API key.
TypeScript SDK on npm as @lictorate/agentguard
:::bash
npm install @lictorate/agentguard@1.1.1
:::ts
import { AgentGuard } from '@lictorate/agentguard';
This first version was published by hand; from the next release, GitHub Actions publishes it through npm trusted publishing, with provenance.
Example MCP configs and the default policy
- The example configs for Claude Desktop, Cursor, Cline, Continue and Zed launch the official servers:
uvx mcp-server-fetchand GitHub'sghcr.io/github/github-mcp-serverimage. Each guide lists the launcher (npx, uvx or docker) each upstream needs. configs/default.yamlsends fetch and GitHub calls to human approval. Approved fetches still pass through the network allow-list; approved GitHub calls run.
Builds
go installbuilds show the update notice from the interactive subcommands, as documented, andagentguard versionprintsmodule vX.Y.Zor a git revision instead ofdev.servestill never makes the check;AGENTGUARD_NO_UPDATE_CHECK=1opts out.make docker-runpassesAGENTGUARD_API_KEY, which the container needs to listen on its published port, and stops with an explanation when the variable is unset.agentguard statussays when the server was started without--dashboardinstead of printing a JSON decode error.
Documentation
Corrected against the code and, where it mattered, against a running server: the MCP and LLM proxy quickstarts, the MCP Gateway and LLM API Proxy references, deployment (Compose now builds the image; the Kubernetes example gained the --policy flag it needed to start), the API reference (SSE event types, status codes, and the previously undocumented POST /v1/audit), both SDK references, the CLI reference, the adapter compatibility matrix, the Go and Node version floors, and SECURITY.md, which now supports the 1.1.x line. The hot-path latency rules CI enforces are now public in CONTRIBUTING.md (github.com).
Corrections to earlier releases
Earlier CHANGELOG entries, release notes and MIGRATION.md are corrected in place, each with a (Corrected in v1.1.1: …) note: the contact address; the TypeScript SDK was not on npm at 0.5.2, 0.9.0 or 1.0.0; no Docker image was ever published; v0.7.0 and v0.4.1 were never published; and links to a design document that was never committed.
Breaking changes
None in the public API: no exported Go identifier, config key, route, wire field, audit format or policy schema changed.
Two behaviour changes can affect an existing setup:
--listen :PORTon the LLM proxy now refuses without--proxy-api-key. This is a fail-closed correction.- The shipped
configs/default.yamlchanged for thefetchandgithubMCP namespaces. A copy you made earlier is unaffected.
Upgrade notes
- Binaries and Python SDK: a swap; nothing on disk changes.
- TypeScript SDK: install
@lictorate/agentguardand change imports from@agentguard/sdk. - LLM proxy: change
--listen :PORTto127.0.0.1:PORT, or add--proxy-api-key. - Rollback to 1.1.0 is safe, but brings back the
--listen :PORThole.
Details: MIGRATION.md § v1.1.0 → v1.1.1 (github.com).
Get started
:::bash
go install github.com/Caua-ferraz/AgentGuard/cmd/agentguard@v1.1.1
go install github.com/Caua-ferraz/AgentGuard/cmd/agentguard-mcp-gateway@v1.1.1
go install github.com/Caua-ferraz/AgentGuard/cmd/agentguard-llm-proxy@v1.1.1
pip install --upgrade "agentguardproxy==1.1.1"
npm install @lictorate/agentguard@1.1.1
# Docker: no image is published; build one from the repository's Dockerfile
docker build -t agentguard:1.1.1 .
Full change list: CHANGELOG.md § 1.1.1 (github.com).